Denial of Service Vulnerability in ClamAV's AutoIt Module
CVE-2023-20212
7.5HIGH
What is CVE-2023-20212?
A vulnerability exists in the AutoIt module of ClamAV that may allow unauthenticated remote attackers to trigger a denial of service condition. This flaw is caused by a logic error in memory management, enabling attackers to submit specially crafted AutoIt files for scanning. If successful, the exploit could lead to the ClamAV scanning process restarting unexpectedly, thereby disrupting services.
Affected Version(s)
Cisco Secure Endpoint